Remote Code Execution Vulnerability in node-opcua by Node-OPCUA
CVE-2026-69200

3.7LOW

Key Information:

Vendor

Node-opcua

Vendor
CVE Published:
16 September 2026

What is CVE-2026-69200?

A vulnerability exists in node-opcua, an OPC UA implementation for TypeScript and Node.js, prior to version 2.145.0. This flaw is found in the fieldsToJson method, where unsanitized field names can lead to unintended manipulation of Object.prototype via an attacker-controlled proto.pollutedKey path. Exploiting this vulnerability may result in denial of service or corruption of application logic, particularly in environments where event fields are exposed to the fieldsToJson method.

Affected Version(s)

node-opcua < 2.145.0

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.